Impact
An input‑validation flaw in nghorta’s sidebarTabs plugin allows attackers to inject arbitrary script into dynamically generated pages. The result is a reflected XSS payload that will execute inside the victim’s browser when they visit a crafted URL or submit a form containing malicious data. This leads to client‑side compromise such as session hijacking, data theft, or defacement.
Affected Systems
The vulnerability exists in the sidebarTabs plugin from nghorta, affecting all releases up to and including version 3.1. Servers or sites running any of those versions are susceptible.
Risk and Exploitability
The CVSS score of 7.1 indicates a high‑moderate severity, while the EPSS score of less than 1% shows the likelihood of exploitation is currently low but not negligible. Because the attack does not bypass authentication and requires user interaction, the exploitvector is likely web‑based via reflected input. The vulnerability is not listed in the CISA KEV catalog, suggesting no confirmed widespread attacks yet.
OpenCVE Enrichment
EUVD